Malicious PDF — malware analysis report

Static analysis result for SHA-256 3d916c7610904066…

MALICIOUS

PDF

76.8 KB Created: 2021-03-21 01:14:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4f5493a29d6be9d613d694071fea53a9 SHA-1: 453e3c8751c8122fb71cbfe104051d6e322558dc SHA-256: 3d916c76109040660321490e9761b0a93b080f7abe467fb7a203471eadefe443
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The file is a PDF identified as malicious by ClamAV and an ML classifier. It contains an embedded URL pointing to a suspicious domain, disguised as sheet music. While no scripts were explicitly extracted, the PDF structure and the presence of external URIs suggest it's designed to trick users into downloading further malicious content or visiting phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://lozipotod.ru/award?keyword=les+choristes+sheet+music+pdf
    • http://jerimujolegem.medianewsonline.com/adapter_class_in_java.pdf
    • http://nusowutevu.getenjoyment.net/classification_of_carbohydrates_download.pdf
    • http://jusojixanona.getenjoyment.net/69639192632.pdf
    • http://vevebopawo.mywebcommunity.org/7044018864.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://s3.amazonaws.com/kakekojezutok/99802742756.pdf
    • https://393102e6-89af-4738-8cad-89662dba8dc5.filesusr.com/ugd/33a16d_656c9748403f4cdea46fe30ca6b92c4d.pdf?index=true
    • http://menerolefu.rf.gd/fb_video_er_for_pc_windows_7.pdf
    • https://uploads.strikinglycdn.com/files/4ee6c895-a479-4da5-8aa4-efa65640fb77/easy_piano_songs_sheet_music_free.pdf
    • https://s3.amazonaws.com/zijivevip/autocad_2016_free_download_with_crack_64_bit.pdf
    • http://gomitobovuni.rf.gd/bobesi.pdf
    • http://paradubufaxeju.rf.gd/18013315218.pdf
    • https://s3.amazonaws.com/kiguteperilodu/fidiravifarizopuz.pdf
    • http://sokurunofizune.rf.gd/celestron_astromaster_114_battery.pdf
    • https://s3.amazonaws.com/xakapudakadu/pimefisenutezuji.pdf
    • https://uploads.strikinglycdn.com/files/b1d0145b-60c7-434c-aa71-e04b0b3ad6cc/zexogefimulemuzinuluzibon.pdf
    • https://s3.amazonaws.com/pidufozu/tratamiento_para_el_covid_19_mexico.pdf
    • https://8d275f60-8e36-4e70-8574-b6d542a617c4.filesusr.com/ugd/dbf6c2_eafa6b4ab83641bba0f913fbceb3b723.pdf?index=true
    • https://ba30dffa-51fe-4caa-9472-6f142403a9bb.filesusr.com/ugd/c2007e_bdf39577031b49f992b021501863474a.pdf?index=true
    • https://f7e05ffc-afae-4d19-be15-7e9c659e5e5f.filesusr.com/ugd/72f62b_056f569cd521485e94233dd2d4e0c27d.pdf?index=true
    • https://uploads.strikinglycdn.com/files/d19104da-74c4-46fd-a7e3-575b2d19785d/how_to_increase_brightness_in_casio_calculator_fx-991ex.pdf
    • https://47a25507-5c4f-4e73-9b7c-0c49514c8174.filesusr.com/ugd/e00bd3_fc70a22be0d24f37842ef0987cc2a974.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e260.bin
db1bc8653878d5bf085edb02d7ecb5510a97a62b1928ad3a9f880f525d963735
pdf-font-stream PDF embedded font (sfnt) at offset 0xE260 4872 bytes
font_01_sfnt_off0000f2f6.bin
f1484569805ad9c5adcd112483c785f0b1fcdabf84b04905c3c6b015b9df6d32
pdf-font-stream PDF embedded font (sfnt) at offset 0xF2F6 10704 bytes
font_02_sfnt_off00011797.bin
7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71
pdf-font-stream PDF embedded font (sfnt) at offset 0x11797 4324 bytes